Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Network & Building Devices Exploited: Zyxel GS1900 CVE-2026-7273, Lantronix EDS5000 CVE-2025-67038, KNX CVE-2023-4346

High CVE-2026-7273, CVE-2025-67038, CVE-2023-4346 — Switches, serial-to-Ethernet gateways and building-automation controllers are on CISA's 2026 exploited list: a Zyxel GS1900 switch command-execution bug, a root command injection in Lantronix device servers, and KNX device lock-out attacks. Firmware fixes and isolation advice.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: The boxes nobody thinks about are getting hit. Zyxel GS1900 smart switches (firmware 2.90 C0 and earlier) let anyone on the LAN run commands via a crafted HTTP request. Lantronix EDS5000, G520, X300 and E210/E220 run commands as root from the login username field. KNX building controllers can be locked with a password their owners can't reset. Update firmware, and put management interfaces on their own VLAN.

CVE-2026-7273Zyxel GS1900 series CGI stack overflow → LAN-side unauthenticated OS command execution. CVSS 8.8. KEV 2026-09-21
CVE-2025-67038Lantronix EDS5000 / G520 / X300 / E210 / E220: username concatenated into a shell command on failed login → root. CVSS 9.8. KEV 2026-06-23
CVE-2023-4346KNX Connection Authorization Option 1: attacker sets a BCU key, owner locked out. CVSS 7.5. KEV 2026-07-15
Lantronix fixedEDS5000 2.2.0.0R1 · G520/X300 2.6.0.4R6 · E210/E220 3.21.0.0R1

Zyxel GS1900 switches: CVE-2026-7273

The GS1900 is a popular small-business and homelab smart switch. A stack overflow in its web-management CGI program lets an unauthenticated attacker on the LAN execute OS commands with a crafted HTTP request. Affected models include GS1900-8, -8HP, -10HP, -16, -24, -48 and their HP/v2 variants on firmware 2.90 C0 and earlier (e.g. 2.90(ABTQ.1)C0 on the GS1900-48HPv2).

  • Check: web UI → Status → System Info, or the firmware string on the login page.
  • Fix: download the patched firmware for your exact model from Zyxel’s advisory and upload it under Maintenance → Firmware; then reboot onto it.
  • “LAN-based” still matters: a compromised PC, a guest on Wi-Fi, or an IoT device on the same VLAN as the switch’s management IP can exploit it. Move switch management to a dedicated VLAN (Management VLAN setting).

Lantronix device servers: CVE-2025-67038

Lantronix serial-to-Ethernet and cellular gateways connect older equipment (PLCs, meters, POS, medical and lab devices) to networks. When a login fails, the HTTP RPC module writes a log entry by running a shell command with the username pasted in unsanitised, so a username like ;command runs as root without valid credentials.

SeriesFixed firmware
EDS5000 (EDS5008/5016/5032)2.2.0.0R1
G520, X3002.6.0.4R6
E210, E2203.21.0.0R1

These devices should never have their web interface reachable from the internet; check with Shodan for your public IPs. Put them behind a firewall that only allows the specific hosts that talk to them.

KNX building automation: CVE-2023-4346

KNX controls lighting, blinds, HVAC and access in many commercial buildings and smart homes. Devices that support KNX Connection Authorization Option 1 let anyone with network access set a BCU key (device password). Often it can’t be reset without knowing the current one, so an attacker can lock you out of your own building controls, which has been used in real attacks. Mitigations:

  • Never expose KNX/IP routers or interfaces (UDP 3671) to the internet; reach them over VPN.
  • Set your own BCU key on devices that support it, so an attacker can’t set one first, and record it securely.
  • Use KNX Secure where the devices support it, and segment the KNX/IP network from office and guest networks.

General advice for “forgotten” devices

  • Make an inventory: every switch, gateway, controller, camera and printer with an IP address.
  • Give infrastructure management its own VLAN, and only allow admin workstations to reach it.
  • Check firmware twice a year at minimum; subscribe to vendor security advisories for anything business-critical.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories